<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you audit user logins on a forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/422998#M74269</link>
    <description>&lt;P&gt;I need to change the admin account password and want to make sure I don't break any automated tasks by doing it. How do I determine if the Splunk admin account has been used to log into and do things on the forwarder?&lt;/P&gt;</description>
    <pubDate>Tue, 29 May 2018 21:12:16 GMT</pubDate>
    <dc:creator>thisissplunk</dc:creator>
    <dc:date>2018-05-29T21:12:16Z</dc:date>
    <item>
      <title>How do you audit user logins on a forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/422998#M74269</link>
      <description>&lt;P&gt;I need to change the admin account password and want to make sure I don't break any automated tasks by doing it. How do I determine if the Splunk admin account has been used to log into and do things on the forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 21:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/422998#M74269</guid>
      <dc:creator>thisissplunk</dc:creator>
      <dc:date>2018-05-29T21:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: How do you audit user logins on a forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/422999#M74270</link>
      <description>&lt;P&gt;The forwarder should be logging user-login events into $Splunk_home/var/log/splunk/audit.log which are monitored and goes to index=_audit (logs are same as what you'll find on your search heads e.g. &lt;CODE&gt;index=_audit sourcetype=audittrail action=login*&lt;/CODE&gt;). AFAIK, forwarding of _audit index data from forwarder is disabled from default, so you'd need to enable that and should be able to monitor user logins.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/422999#M74270</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-29T19:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do you audit user logins on a forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/423000#M74271</link>
      <description>&lt;P&gt;Great thank you. So if I don't see the admin account appearing in this year's audit log events I should be good?&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 22:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/423000#M74271</guid>
      <dc:creator>thisissplunk</dc:creator>
      <dc:date>2018-05-29T22:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do you audit user logins on a forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/423001#M74272</link>
      <description>&lt;P&gt;Yes. But I'm not sure the logs will be available for that long. Check the retention period of _audit index.&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 01:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/423001#M74272</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-05-30T01:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do you audit user logins on a forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/423002#M74273</link>
      <description>&lt;P&gt;Grepping through the splunk/var/log on the server in question did it.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 22:08:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-audit-user-logins-on-a-forwarder/m-p/423002#M74273</guid>
      <dc:creator>thisissplunk</dc:creator>
      <dc:date>2018-06-07T22:08:13Z</dc:date>
    </item>
  </channel>
</rss>

